From efcc23f51aacc2b81ebfdd8737e86b3e1b86363f Mon Sep 17 00:00:00 2001 From: Micah Anderson Date: Thu, 15 Sep 2005 23:11:08 +0000 Subject: Prepare DTSA-17-1 git-svn-id: svn+ssh://svn.debian.org/svn/secure-testing@2011 e39458fd-73e7-0310-bf30-c45bca0a0e42 --- website/DTSA/DTSA-17-1.html | 93 +++++++++++++++++++++++++++++++++++++++++++++ website/list.html | 2 + 2 files changed, 95 insertions(+) create mode 100644 website/DTSA/DTSA-17-1.html (limited to 'website') diff --git a/website/DTSA/DTSA-17-1.html b/website/DTSA/DTSA-17-1.html new file mode 100644 index 0000000000..18e597b6ce --- /dev/null +++ b/website/DTSA/DTSA-17-1.html @@ -0,0 +1,93 @@ + + + Debian testing security team - Advisory + + + + +
+ + + + + Debian Project +
+
+ + + + + + + + + + + +
+ Debian testing security team - Advisory +
+ + +
+ + +

DTSA-17-1

+
+
Date Reported:
+
September 15th, 2005
+
Affected Package:
+
lm-sensors
+
Vulnerability:
+
insecure temporary file
+
Problem-Scope:
+
local
+
Debian-specific:
+
No
+
CVE:
+
+CAN-2005-2672 +
+
More information:
+
Javier Fernández-Sanguino Peña discovered that a script included in 
+lm-sensors, used to read temperature/voltage/fan sensors, creates a temporary 
+file with a predictable filename, leaving it vulnerable for a symlink 
+attack. 

+Note that this is the same set of security fixes put into stable in 
+DSA-814-1. 
+
+
For the testing distribution (etch) this is fixed in version 1:2.9.1-6etch1
+
For the unstable distribution (sid) this is fixed in version 1:2.9.1-7
+
This upgrade is recommended if you use lm-sensors.
+
If you have the secure testing lines in your sources.list, you can update by running this command as root:
+ +
apt-get update && apt-get install lm-sensors
+
+ +
+
To use the Debian testing security archive, add the following lines to your /etc/apt/sources.list:
+
+
deb http://secure-testing-mirrors.debian.net/debian-secure-testing etch-proposed-updates/security-updates main contrib non-free
+
deb-src http://secure-testing-mirrors.debian.net/debian-secure-testing etch-proposed-updates/security-updates main contrib non-free
+
+
The archive signing key can be downloaded from
+
http://secure-testing.debian.net/ziyi-2005-7.asc
+ +
+ + +
+ + Valid HTML 4.01! + + Valid CSS! + + + + diff --git a/website/list.html b/website/list.html index bd2cad3c66..d53f10931f 100644 --- a/website/list.html +++ b/website/list.html @@ -69,6 +69,8 @@
several vulnerabilities
[September 15, 2005] DTSA-16-1 linux-2.6
various
+
[September 15th, 2005] DTSA-17-1 lm-sensors
+
insecure temporary file

-- cgit v1.2.3